Granular DRM for Email Attachments via Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital rights management systems for emails are inflexible, as they apply the same protection policy to the entire MIME format email, including both the message and attachments, making it difficult to manage different access permissions for various users and scenarios, such as allowing access to attachments for one set of users while allowing access to the email message for a different set or revoking access permissions.
Innovation Solution
A method that allows different digital rights management policies to be applied to different components of an email, such as the email body and attachments, by using a client computer and a digital rights management server to encrypt and decrypt the email, apply individual DRM policies to attachments, and re-compose the email with protected attachments, enabling separate access control for each component.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If one DRM policy is applied to the entire MIME format email including attachments, then the DRM system is simple to implement, but it lacks flexibility to manage different access permissions for email body and attachments separately
Solution Approach 1:
The patent segments the email into separate components (email body and attachments) and applies different DRM policies to each component. The system processes the email to identify attachments, then applies distinct access permissions to each attachment independently from the email body, enabling granular control over what recipients can access.
Solution Approach 2:
The patent implements local quality by allowing different security attributes and DRM policies to be applied to different parts of the email (body vs. attachments). Each attachment can have its own set of security attributes, enabling the system to tailor access permissions locally to each component rather than applying a uniform policy globally.
2Adaptability or versatility
If separate DRM policies are applied to email body and attachments, then access control flexibility is improved, but processing complexity increases
Solution Approach 1:
The patent performs preliminary action by pre-processing the email to identify and separate attachments before applying DRM policies. The system scans the email content, identifies attachment files, and prepares them for separate policy application. This preliminary segmentation simplifies the subsequent policy application process rather than complicating it.
Solution Approach 2:
The patent introduces an intermediary processing layer that mediates between the email body and attachments. This intermediary component handles the complex task of separating attachments, applying appropriate DRM policies, and reassembling the email, thereby isolating the complexity from both the user interface and the core DRM system.
3Ease of operation
If separate DRM policies are applied to different email components, then user-friendliness is improved through better permission management, but the number of DRM policies required increases
Solution Approach 1:
The patent implements universality by creating a multi-functional DRM system that can handle both email bodies and attachments with a single integrated framework. The system uses a universal policy application mechanism that works across different email components, allowing administrators to manage permissions through a unified interface rather than requiring separate policy management systems for each component type.
Data Source
AI summary
A digital rights management (DRM) method for protecting emails can apply different protection policies to different components of an email such as the message body and the attached digital files. While an email application of the client encrypts the entire email document including both the message and the attachments, a plugin module on the client obtains user input regarding the DRM policies to be applied to individual attachments and then transmits the encrypted email along with the information about the DRM policies for the individual attachments to a digital rights management server. The server first decrypts the entire email document, then applies the user-specified DRM policies to the attachments individually. The server re-composes an email and attaches the individually protected attachments, and transmits the email to the exchange server.


